← Vulnerability feed

Vulnerability record · CVE-2025-56427 · published 4 December 2025

CVE-2025-56427: Composio information exposure vulnerability

Composio · Composio

Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function.

7.5 CVSS 3.1 High EPSS 0.89% · top 42.4% CWE-200 · Information exposure
7.5CVSS 3.1 base score
0.89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-56427 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-8958Composio unrestricted file upload vulnerabilityIn composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation…EPSS 1.4%9.8CVE-2024-8953Composio improper control of dynamically-managed code vulnerabilityIn composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This c…EPSS 1.2%9.8CVE-2024-8954Composio vulnerabilityIn composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability al…EPSS 0.87%7.5CVE-2024-8955Composio server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the co…EPSS 0.73%7.5CVE-2024-8952Composio server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCR…EPSS 0.72%6.4CVE-2024-53526Composio command injection vulnerabilitycomposio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.EPSS 0.59%5.1CVE-2024-8864Composio code injection vulnerabilityA vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculat…EPSS 0.83%5.1CVE-2024-8865Composio path traversal vulnerabilityA vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file c…EPSS 0.87%

Source: NIST National Vulnerability Database (record CVE-2025-56427), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.